03 June 2012

NLE 2012: Trustworthiness of the System...

The National Level Exercise (NLE) 2012 Capstone will soon be taking place and the private sector is embracing for potential cyber domain blowback.  NLE 2012 is based upon an exercise scenario that is not only timely, but also an expanding Operational Risk to the U.S. critical infrastructure.  This comes months after the secure communications channel has been established between Washington and Moscow, in the event of a damaging digital attack to prevent any escalation to full hostilities.

National Level Exercise (NLE) 2012 is part of a series of congressionally mandated preparedness exercises designed to educate and prepare participants for potential catastrophic events. The NLE 2012 process will examine the nation’s ability to coordinate and implement prevention, preparedness, response and recovery plans and capabilities pertaining to a significant cyber event or a series of events. NLE 2012 will examine national response plans and procedures, including the National Response Framework (NRF), NRF Cyber Incident Annex, Interim National Cyber Incident Response Plan (NCIRP) and the International Strategy for Cyberspace. Unique to NLE 2012 will be an emphasis on the shared responsibility among all levels of government, the private sector and the international community to secure cyberspace and respond together to a significant cyber incident.

Simultaneously, the  U.N.'s International Telecommunication Union (I.T.U.) is mediating the future of the Internet.  Hamadoun Toure will be meeting in Dubai as I.T.U. secretary-general later this year as 193 nation states debate the new rules of engagement.   The lines have already been drawn in the sand between rogue groups and Western democracies, private companies, law enforcement and hacktivists.

As strategic media leaks are continuously debated and clandestine operations are exposed, the Operational Risks for the private sector continue to soar.  Whether it is the threat to the Olympic Games in London this summer or the covert "Olympic Games" in cyberspace, there continues to be a set of consistent taxonomy developed years ago by Sandia Labs researchers, that this blog has highlighted before:
"Attackers use tools to exploit vulnerabilities, to create an action on a target, that produces an unauthorized result to obtain their objective."
The three areas that you need to focus on continue to be:
  • Design
  • Implementation
  • Configuration

Whether it is through physical attack, information exchange, user commands, scripts, programs, autonomous agents, toolkits or data taps you can be assured that these tools are being utilized to exploit you. They are being directed at the design, implementation or configuration of your "Controls" in order to achieve the action they desire:

  • Probe
  • Scan
  • Flood
  • Authenticate
  • Bypass
  • Spoof
  • Read
  • Copy
  • Steal
  • Modify
  • Delete
All of these actions are directed at their target. Accounts, people, processes, data, components, computers, networks or internetworks. They are looking for and unauthorized result:
  • Increased Access
  • Disclosure of Information
  • Corruption of Information
  • Denial of Service
  • Theft of Resources
And sadly, when you boil it down to the reasons or objectives they seek to achieve; it usually falls into one of four categories:
  • Challenge, Status, Thrill
  • Political Gain
  • Financial Gain
  • Damage
Once you understand the entire taxonomy of an "Incident", you are far better equipped to prevent and preempt attacks on your valuable corporate assets.
Now the question to be answered is, who is your adversary?  Answering this question and putting a face on those who are attacking you, somehow seems to be more important these days by some.  Attribution is only one key facet of asymmetric warfare.



at·tri·bu·tion

  [a-truh-byoo-shuhn]  Show IPA
noun
1.
the act of attributing ascription.
2.
something ascribed; an attribute.
3.
Numismatics a classification for a coin, based on itsdistinguishing features, as date, design, or metal.
4.
Archaic authority or function assigned, as to a ruler,legislative assembly, delegate, or the like.


at·trib·ute

  [v. uh-trib-yoot; n. a-truh-byoot]  Show IPA
verb, at·trib·ut·ed, at·trib·ut·ing, noun
verb (used with object)
1.
to regard as resulting from a specified cause; consider ascaused by something indicated (usually followed by to ): She attributed his bad temper to ill health.
2.
to consider as a quality or characteristic of the person, thing, group, etc., indicated: He attributed intelligence to his colleagues.
3.
to consider as made by the one indicated, especially withstrong evidence but in the absence of conclusive proof: to attribute a painting to an artist.
4.
to regard as produced by or originating in the time, period, place, etc., indicated; credit; assign: to attribute a work to particular period; to attribute a discovery to a particular country.
noun
5.
something attributed as belonging to a person, thing, group,etc.; a quality, character, characteristic, or property:Sensitivity is one of his attributes.


Regardless of the ability to attain the identity of your attacker, your focus should remain on your trusted systems and your resilience factor.  The trustworthiness of the system requires evaluation and a trust decision to use the system.  "The risk calculus evaluates whether the probability that the services as a result of using the system, will exceed the risks that may occur as valued by a user.  The cost component of a trust decision includes an evaluation that the use of a system will occur at an acceptable cost and will produce economically acceptable results."  [US 7240213]

19 May 2012

Telecom DataTecture: Cloud Resilience in 4GW...

The Enterprise Cloud computing environment is not only a topic of many private sector CIO forums this year, it is also spawning new discussions in government intelligence community circles. Simultaneously, the new economics and the aversion to buying hardware and software to house your own brick and mortar data center, is slowly but surely taking the business community by storm.

Companies such as Terremark Worldwide that already serves some of the most highly classified data traffic and storage for the intelligence and other civilian agencies, is gaining tremendous momentum in the marketplace. Why? Visit their NAP of the Capital Region 60 miles or so outside Washington, DC and you will witness part of the answer. The other part of why can be found in Terremark's sophisticated VMware-powered "Infinistructure" that provides the modern enterprise to more easily scale in bandwith and storage commensurate with daily, weekly or monthly utilization of dynamic computing utility requirements.

In order for a Small-to-Medium-Enterprise (SME) to grow with new HP or IBM Servers, EMC or NetAPP storage and sub-systems for load balancing, back-up power generation, disaster recovery and managed security services requires a substantial new Capital Expenditure (CAPEX). This strategy for a Telecom DataTecture (Cloud Data Centers) is one that architects of critical infrastructure resiliency teams can no longer ignore.

What does "Business Resilience" and critical infrastructure have to do with Operational Risk Management? At the core of OPS Risk is the concept that vulnerabilities exist in your organization across a spectrum of people, processes, systems and external events. Executives now have a new mindset that sounds like this. "I know that it's just a matter of time until we experience a significant business disruption to the organization. Now the question remains, what, who, when, where and how?". By the "Insider" who has been stealing precious intellectual property or facilitating some occupational fraud scheme to the "External" attacker that enables a data breach of "Personal Identifiable Information" (PII) at a minimum. The serious adversary will only care about major disruption or destruction; Mother Nature (Haiti) or Aurora (Hack).

Once you have achieved this mindset and the reality of the future attack, you transition to "Enabling Enterprise Business Resiliency" and a series of measures towards your own survivability. These measures in the Information Technology sector of your business or government enterprise will determine your future posture in a post incident cyber scenario. The magnitude of the incident itself is growing on a vector that now even Richard Clarke has shed more light on:

CYBER WAR:
THE NEXT THREAT TO NATIONAL SECURITY AND WHAT TO DO ABOUT IT

Cyber War is a powerful book about technology, government, and military strategy; about criminals, spies, soldiers, and hackers. This is the first book about the war of the future -- cyber war -- and a convincing argument that we may already be in peril of losing it. 
Cyber War goes behind the "geek talk" of hackers and computer scientists to explain clearly and convincingly what cyber war is, how cyber weapons work, and how vulnerable we are as a nation and as individuals to the vast and looming web of cyber criminals. From the first cyber crisis meeting in the White House a decade ago to the boardrooms of Silicon Valley and the electrical tunnels under Manhattan, Clarke and coauthor Robert K. Knake trace the rise of the cyber age and profile the unlikely characters and places at the epicenter of the battlefield. They recount the foreign cyber spies who hacked into the office of the Secretary of Defense, the control systems for U.S. electric power grids, and the plans to protect America's latest fighter aircraft.

The warnings and doom and gloom has been around for years and one more book will not likely change the current state of cyber arm wrestling going on around the Washington, DC 495 beltway. The Net-centric warrior of the next decade will no doubt have to rely on a much more resilient set of technologies and countermeasures to circumvent the latest nations state cyber armies, or cyber criminal syndicates. Even more important is the current state of the domestic ability to withstand the 4th Generation Warfare (4GW) being waged on our financial, energy and defense industrial base.

This asymmetry, in which we are developing offensive capability but doing little to prevent a devastating cyber attack, began in the Bush administration. In the last year of his eight-year presidency, George W. Bush signed a national-security decision called PDD-54. That directive, still classified, ordered steps be taken to improve the security of the Department of Defense and other federal-government computer networks. Critics say it did almost nothing to address the weaknesses of the national infrastructure.

13 May 2012

Red Alert: Operational Risk Quotient...

Operational Risk is in the U.S. news again this past week.  Several prominent CEOs and the Board of Directors are under fire in the United States for failures to comply with documented best practices and governance processes.  The failure to execute these processes for the effective management of Operational Risk has now become a "Red Alert" for organizations in the financial services and banking industry.   The ranks of those tasked with vetting and validating candidates for high profile positions in public companies are also under increased scrutiny.  We should look at these one at a time.  JPMorgan first:

FAIR GAME
At JPMorgan, the Ghost of Dinner Parties Past
By 
Published: May 12, 2012 
WHAT goes around comes around. Sometimes it happens sooner than you’d think.  That round wheel turned on JPMorgan Chase last week, which disclosed that it had suffered a $2 billion trading loss in credit derivatives. That such a hit had befallen the mightiest of banks was perhaps more stunning than the size of the loss. 
So where does the karma come in? The loss, and the embarrassment it held for Jamie Dimon, the bank’s imperious chief executive, came just one month after a private dinner party in Dallas at which he assailed two respected public figures who have pushed for policies that would make banks like JPMorgan smaller and less risky. 
One was Paul Volcker, the former Federal Reserve chairman, whose remedy for risky trading by too-big-to-fail banks is known as the Volcker Rule.


The story is not about losing $2B. USD in trading derivatives.  And as Gretchen Morgenson has stated, we are witnessing a paradox.  The same rules JPMorgan is opposing in regard to proprietary trading could very well be the same rules that could provide a "Red Alert" that a threat is on the horizon.  The cost to the institution is far beyond the loss of the trade in terms of reputation and overall market value.  The credit ratings agencies and the SEC are now moving into place for their respective response to this incident.

Now let us take a look at Yahoo and a CEO who is embroiled in an error on his curriculum vitae:

Exclusive: Yahoo’s Thompson Out; Levinsohn In; Board Settlement With Loeb Nears Completion  Published on May 13, 2012  
by Kara Swisher 
Yahoo’s embattled CEO Scott Thompson (pictured here) is set to step down from his job at the Silicon Valley Internet giant, in what will be dramatic end to a controversy over a fake computer science degree that he had on his bio, according to multiple sources close to the situation. 
The company will apparently say he is leaving for “personal reasons.”  But the evolving crisis — which is just over a week old — centered on his botched resume and how he handled the thorny issue is clearly the key reason for the abrupt leaving.

This Operational Risk loss is a failure of a process that may have been outsourced to an executive recruiting firm or to the Board Director responsible for the vetting and validation of each candidates information.  What is even more compelling to think about are all of the other CEOs that are now losing sleep over night because of the same issue at their own organization.  So where did someone go wrong in this case?  Was it a missed step in the process for hiring or a simple lack of integrity by the CEO himself, Scott Thompson?

This brings us to the convergence of our discussion on Operational Risk Management for both of these incidents.  There are aspects of transparency, governance and finding the truth.  And the truth is, we are all human.  Whether we are trading derivatives to hedge risk or we are vetting the information on a resume, the human factors and behavior associated with the actual risk management tasks themselves are the focus here.  Humans will make mistakes and that is precisely why we need the controls in place, to mitigate the potential for human error, omission and stupidity.

You see, it is the rules that matter in either case that have been ignored, disregarded or as a result of a lack of awareness.  The rule-sets are vital to the effectiveness of risk management whether they are best practices, international standards of conduct or the code of law within a particular jurisdiction.  These rule-sets have been discussed on this blog in the past, back in April of 2008:  Rule-Set Reset and others such as this one in May of 2004 on NYSE Rule 446:

Operational risk focuses on firms' abilities to maintain communications with customers and to retrieve key activity records through their "mission critical systems." Financial risk relates to firms' abilities to continue to generate revenue and to retain or obtain adequate financing and sufficient capital. In this regard, an eroding financial condition could be exacerbated or caused by deterioration in the value of a firm's investments due to the lack of liquidity in the broader market, which would also hinder the ability of the firm's counter-parties to fulfill their obligations. A firm would be expected to periodically assess changes in these exposures, and in the event of a significant business disruption, the firm would consult its plan and take appropriate action contemplated by its plan. Members' and member organizations' procedures should be written and implemented to reflect the interrelationship among these risks.

What rule-sets govern your organization?  Have you created a comprehensive governance map to help you guide yourself as a CEO and the remainder of your company through the maze of ethical, regulatory, legal and even sustainable rules that are before you?  Leadership in any organization whether it is in Silicon Valley, on Wall Street or the US Navy requires a prudent and clear path, to understanding the rules and the map to navigate both securely and safely.  Even with these rules and the map, you can predict that human behavior will intervene and deliver that next surprising blow to your institution.  Now it is just a matter of how often and the magnitude of the event.

Ask yourself:  What is our "Operational Risk Management" Quotient?


22 April 2012

Workplace Trust: Integrity, Ethics & Legal Risk...

Operational Risk Management professionals wonder about the "Tone at the Top" and decisions at the latest Board of Directors meetings to ignore or investigate a whistleblowers claims of ethics or governance violations in the workplace.

The financial services companies have for years been the target of scrutiny for claims of fraud, mistreatment of consumers and violations of several U.S. federal regulations many under further examination by the SEC.  As time goes on in the evolution of maleficence you will find examples of wrong doing in other private sector areas, such as the Defense Industrial Base (DIB), Retail and Information Technology (IT).  Think about your own company and ask yourself how you treat and respond to the 800 number Ethics Line and those who staff the Internal Audit, Risk Management or Information Security departments.  Are these enablers or impediments to your future success?  Your answer may be a clue to the issue at hand.

The professionals in the Inspector Generals office, the Operational Risk Management department and the General Counsels office are also there for a good reason.  Think about them as the last "Thin Blue Line" between your company becoming a success or falling into a cultural abyss that will plague the institution for decades.  Steven Pearlstein explains from the Washington Post:

Steven Pearlstein: How could SAIC miss this? By , 
Last week in these pages, The Post ran a profile of John Jumper, the straight arrow former Air Force general who was brought in as chief executive of local contracting giant SAIC in the wake of an embarrassing overbilling scandal involving bribery, kickbacks, foreign shell corporations and a safe deposit box stuffed with $850,000 in cash. 
A year ago company officials were publicly denying that there were any problems at all with its contract to build a new timecard system for New York City, which by then was so late and so over budget that “CityTime” had become a frequent target for the New York tabloids and political embarrassment for Mayor Michael Bloomberg. 
It was just last June that SAIC executives and directors first informed shareholders that there might be a little $2.5 million overbilling problem with the contract and that federal prosecutors had brought criminal charges against six employees of an SAIC subcontractor. Shareholders had to read deep into Note 9 of that quarterly report to learn that there might be “a reasonable possibility of additional exposure to loss that is not currently estimable” that “could have a material adverse impact” on the company’s finances.


This episode by one DIB contractor, was not the first nor will it be the last.  One has to ask whether the advice these companies are getting from their outside counsel is always the right course of action.  The government and the internal risk management departments are going to be continuously deluged with new whistleblower claims.  Not just because new laws are in place to protect them and to provide them with the incentives to come forward.  It is because good people are sick and tired of having their organizations reputation tarnished and their respective ethical practices being jeopardized by a few bad cowboys or rogue actors.  Yet now, the Retail sector is being taught a serious lesson regarding a potential FCPA violation by Wal-Mart.  David Barstow at the NYT has this to report:

By  
Published: April 21, 2012  MEXICO CITY — 
In September 2005, a senior Wal-Mart lawyer received an alarming e-mail from a former executive at the company’s largest foreign subsidiary, Wal-Mart de Mexico. In the e-mail and follow-up conversations, the former executive described how Wal-Mart de Mexico had orchestrated a campaign of bribery to win market dominance. In its rush to build stores, he said, the company had paid bribes to obtain permits in virtually every corner of the country. 
The former executive gave names, dates and bribe amounts. He knew so much, he explained, because for years he had been the lawyer in charge of obtaining construction permits for Wal-Mart de Mexico. 
Wal-Mart dispatched investigators to Mexico City, and within days they unearthed evidence of widespread bribery. They found a paper trail of hundreds of suspect payments totaling more than $24 million. They also found documents showing that Wal-Mart de Mexico’s top executives not only knew about the payments, but had taken steps to conceal them from Wal-Mart’s headquarters in Bentonville, Ark. In a confidential report to his superiors, Wal-Mart’s lead investigator, a former F.B.I. special agent, summed up their initial findings this way: “There is reasonable suspicion to believe that Mexican and USA laws have been violated.”

Mitigation of Operational Risks in the workplace, such as fraud and corruption is different than it is outside the enterprise.  The difference is, that corporate executives do not always believe that their own employees would behave this way.  They could be naive to the reasons why fraud finds its way into the psyche of some of the organizations must trusted officers.  Corruption and the signs that an organization has lost its way from a place of cultural integrity and one that condones others to look the other way or for many to help perpetuate schemes of wrong doing, requires a massive organizational transformation.  A transformation that is lead by focused and talented Operational Risk professionals.

But most of all, even if you have these professionals on your team already, there are still some important ingredients to achieving your own "Defensible Standard of Care":

1.  If you think you have funded the risk management department in your enterprise adequately, you haven't.  Do not confuse your outside audit function with your internal risk management function. 
2.  If you don't understand how your 800 number ethics line works and the outsourced organization that runs this, then you need to do so immediately. 
3.  If you have a favorite outside counsel to help you with investigations, it might be time for a check up.  Even more importantly, it might be time to get your outside counsel firms and your outside audit firms invited to a meeting of the minds on corporate integrity. 
4.  If you find any indications that 1 through 3 have been ignored, pushed aside or been giving you a false sense of security, then you might consider making a career change.

Tech Inc., a rapidly growing software company operating in 45 countries, learns that the U.S. Department of Justice (DOJ) and the Securities and Exchange Commission (SEC) are investigating payments made by its subsidiaries in Brazil and China for possible violation of the Foreign Corrupt Practices Act (FCPA). Bob, the general counsel for Tech Inc., suspects that the source of the investigation is an employee who anonymously lodged a hotline complaint alleging that the company was 1) paying independent sales agents excessive commissions and 2) providing generous discounts and rebates to some of its channel customers and distributors. The complainant also said he believed the problem extended beyond Brazil and China based on discussions he had with other employees.


14 April 2012

Too Big to Fail: Basel III to ID Theft...

Now that the Basel III wheels are in motion and the "Top 29" vital Global banking institutions have been identified, Operational Risk Management is on everyones mind. The capital reserves will continue to assist them in becoming more resilient to the systemic volatility ahead. Are you feeling the uncertainty starting to disappear? Not for a minute.

As these banking institutions try to withstand the economic impact of a nation state failure like Greece, the consumers who are the customers of the "Top 29" too big to fail, are being simultaneously barraged and systemically targeted by international crime rings. Identity thieves have set up transnational operations, that will continue to plague millions of consumers at these same banking institutions. Their own governments continue to try and deal with the nexus of criminal elements, consumer privacy and law enforcement. How bad is it for the U.S. Treasury, as one example:
Identity theft involving tax fraud is increasing faster than law enforcement and government officials can deal with it, according to testimony today before a House oversight subcommittee. Identity theft to scam fraudulent tax refunds from the government has increased 100 percent in just three years.
”As of Aug. 31 of this past year, IRS incident tracking reports indicated that the numbers of taxpayers affected by identity theft has more than doubled since 2008 to over 580,000 taxpayers this year alone,” said J. Russell George, Treasury Department inspector general for tax administration.
The crime has become too easy. It’s like a party, according to Rep. Richard Nugent, R-Fla., whose district has a problem with tax-related identity theft.
“Tampa Police Department has busted what the lawbreakers call ‘make it rain’ parties, where criminals get together in a hotel room with Internet access and file fake return after fake return,” Nugent told the committee.
How does paying out billions of dollars to these fraud crime rings using your social security number and date of birth increase the operational risks on our banking institutions? Everyone who is a consumer at one of these banks who is a victim of fraud, will one day deal with the aftermath. If the fraudsters are filing a fraudulent tax return that impacts you, then the odds are that you may end up paying a higher interest rate and this will not be the only place they are using your ID Theft misfortune for financial gains.
For the victims of tax fraud identity theft, the people who had fraudulent tax returns filed in their names, getting the problem fixed and their lawful refund paid could take a year and a half.
“A typical path for an identity theft refund case that is not complex may take as long as 18 months to resolve,” said J. Russell George, Treasury Department Inspector General for tax administration.
The cost of dealing with Identity Theft has so many dimensions. The protection of Personal Identifiable Information (PII). The fact that the IRS and law enforcement have difficulty sharing information on the consumers themselves due to privacy laws. The technology and online Internet forums for buying and selling fraudulent identities is prevalent. The continuous salvo of attacks on financial institutions to compromise the cyber defenses that they have established is a 24 x 7 battle.

To exacerbate the problem, the "Death Master File" (DMF) is the genesis for much of the Identity Theft and tax fraud when this information gets into the wrong hands. The U.S. Social Security Administration has been publishing this list of 90 million dead Americans since 1980 to help the "Top 29" fight fraud. At the same time, the Identify Theft fraudsters are using the same data to perpetuate their schemes:

Identity thieves are cashing in on dead children across the nation, stealing their Social Security numbers to collect fraudulent tax refunds from the Internal Revenue Service.
Grieving families — including the Watters family of Lake Forest — say their anguish is amplified by the realization that the crooks get help from an unexpected source: the Social Security Administration’s “Death Master File,” which records and lists information about everyone who dies in the United States.
Armed with the deceased child’s Social Security number and other personal information, crooks falsely claim them as dependents and have the refunds routed to them.

One reason that the financial institutions, government agencies and law enforcement are going in circles is because "Operational Risk Management" processes and tools are still not as robust as they could be. As the Basel III regulatory mandates kick in along with other new laws, methods and tools, all of the impacted parties will get better at deterring, detecting, defending and documenting in this complex information age.

In the mean time, consumer beware. Look long and hard at the "Top 29" list and decide if you need to move your funds to somewhere else. And before you do, look at the online banking login page for that institution. Are they still using only a single factor user name and password? Multi-factor authentication is not fool proof, yet it does tell us whether the institution is serious about Operational Risks in the area of Information Security. This is a key indicator of their ability and capability to try and keep your data out of the hands of the transnational eCrime rings.

Finally, you have to take the monitoring of your own Identity, and all of your family members identities seriously. It will be far more proactive, than anything else that will be done by governments or financial institutions alone. Regardless how fast they implement the latest tools and technology the fraudsters are moving just as fast. By adding your own diligence on top of the banking institution, government agency or other entity (Doctors / Lawyers / Dentists/ Insurers) that may have your Personal Identifiable information, you are decreasing your odds of becoming an Identity Theft and fraud victim.

Financial risks for the banks and the consumers will continue to be the current state-of-play. Basel III alone will not eliminate the threat of failure or the possibility of a serious bank fraud. Monitoring services or checking your credit report on a quarterly basis, will not keep the ID Theft criminals from stealing your PII. Implementing both on a proactive and pervasive basis will make a positive difference over time. This is what Operational Risk Management is all about, in the global institution board room and at your own home office.

18 March 2012

Product Innovation: Individual Responsibility for Risk Management...

The next generation of Operational Risk Management professionals will be focused on a whole new set of thinking. Mitigating business risks that are associated with running the day to day functions of the enterprise will require people who have a command of their own accountability. The management of risks in their particular area of operations, will have an acute sensitivity to the level of experimentation, testing and innovation. This responsibility for individual levels of proactive risk management, begins with a new mind-set shift about the world of work itself, and our own management of our personal work product.

When you analyze where the financial services industry has exposed itself to tremendous losses over the years, it will no doubt be tied to some innovative instrument or product that was invented by some very creative and innovative people. These losses surrounding Credit Default Swaps (CDS) or Collateralized Debt Obligations (CDO) as an example, all started when an innovative person utilizing the latest tools available created a new product to be introduced to the marketplace. Sure, there were risk management professionals involved in the pipeline to production including lawyers, math quants and finance experts. Yet a failure of Operational Risk Management, led to serious losses and a global crisis, that may well be just the precursor to something even more sinister.

The humans quest for innovation, creativity and the ability to adapt is built into our DNA. So is the ability to survive and to overcome the adversities of our environment to sustain ourselves. Whether that is in the form of food and water or capital and manpower doesn't really matter. Leveraging the available resources to stay alive, being competitive and gaining more power in the conference rooms of Wall Street, or the Madrasahs in South Waziristan, remains a constant.

Innovation in the workplace, is vital for our employees to thrive and for new products to be discovered and old ones to be enhanced. Those new products are invented by people who will have the simultaneous task of doing a sound operational risk assessment. Managing risks at the same time you are innovating, is hard to separate from each other. The trade-offs and the decisions on whether to use this material or algorithm based upon use, shelf-life and the environment that the new product innovation will be operating in, takes prudent risk analysis.

So what will be different for our next generation of Operational Risk Management professionals? What will the new thinking be all about? It will be about engineering the four-step process into everything we do, and to reinforce the compliance with each step of the teams process:


1. Assess the situation.

The three conditions of the Assess step are task loading, additive conditions, and human factors.

  • Task loading refers to the negative effect of increased tasking on performance of the tasks.
  • Additive factors refers to having a situational awareness of the cumulative effect of variables (conditions, etc.).
  • Human factors refers to the limitations of the ability of the human body and mind to adapt to the work environment (e.g. stress, fatigue, impairment, lapses of attention, confusion, and willful violations of regulations).
2. Balance your resources.

This refers to balancing resources in three different ways:

  • Balancing resources and options available. This means evaluating and leveraging all the informational, labor, equipment, and material resources available.
  • Balancing Resources verses hazards. This means estimating how well prepared you are to safely accomplish a task and making a judgement call.
  • Balancing individual verses team effort. This means observing individual risk warning signs. It also means observing how well the team is communicating, knows the roles that each member is supposed to play, and the stress level and participation level of each team member.
3. Communicate risks and intentions.
  • Communicate hazards and intentions.
  • Communicate to the right people.
  • Use the right communication style. Asking questions is a technique to opening the lines of communication. A direct and forceful style of communication gets a specific result from a specific situation.
4. Do and debrief. (Take action and monitor for change.)

This is accomplished in three different phases:

  • Mission Completion is a point where the exercise can be evaluated and reviewed in full.
  • Execute and Gauge Risk involves managing change and risk while an exercise is in progess.
  • Future Performance Improvements refers to preparing a "lessons learned" for the next team that plans or executes a task.

So what does the renewed emphasis on the process being embedded into our work actually do for our work product? It gives the human a sense that the innovation is now ready for experimentation and field testing. This means that it is still not ready for prime time or the marketplace. You see, this realization is important. The recent focus on rapid prototyping and a push to get products to the marketplace before the competition, has produced the sinister and evil outcomes we have all witnessed. Why does it take so long for a new drug to make it through the pharmaceutical pipeline and end up being advertised on the CBS Evening News?

And even then, after so much testing and study, we find that a new drug (product) is not really so safe compared to the long term complications of using it as prescribed. The risk reward equation is at stake in our financial services industry and every other economic sector that is striving to be more innovative in todays global marketplace: For individuals, here are $18 Million reasons:

Attorney Lynn Szymoniak had spent a career investigating insurance fraud when a bank moved to foreclose on her Florida home in 2008. Almost four years later, the fraud she said she uncovered by combing through mortgage documents earned her $18 million.

Szymoniak, 63, is among six whistle-blowers who will pocket $46.5 million as part of a $25 billion national foreclosure settlement that state and federal officials reached in February with five banks, including Bank of America Corp. andJPMorgan Chase & Co. (JPM), according to the U.S. Justice Department.

“When they did this to her, they picked the wrong person at the wrong time in the wrong place,” Richard Harpootlian, Szymoniak’s attorney in two whistle-blower cases, said in an interview. “They stuck their hand into the beehive.”

Szymoniak’s examination, in which she relied on her experience as an insurance-fraud investigator, led to her claims against banks for submitting fraudulent documents to the federal government asserting that they owned loans insured by the Federal Housing Administration, she said.

The national foreclosure settlement with the five banks, which resolves claims of abusive foreclosure practices, provides mortgage relief to borrowers, pays $1.5 billion to those who lost their homes to foreclosure, and sets standards for how the banks service mortgage loans.

Who will be your choice for effective operational risk management as your new innovative products are consumed by the marketplace?

A. Your employees or workplace stakeholders

B. Your customers or consumers

The choice is yours as your institution puts new resources and new incentives in front of your workplace stakeholders.